SUSE-SU-2018:0246-1
Dashboard / Vulnerabilities / SUSE-SU-2018:0246-1
SUSE-SU-2018:0246-1
Summary: Security update for xorg-x11-libs
Details: This update for xorg-x11-libs fixes several issues. These security issues were fixed: - CVE-2017-16612: Heap overflows due to an integer overflow while parsing images and a signedness issue while parsing comments (bsc#1065386). - CVE-2017-13720: Improper check for end of string in PatterMatch caused invalid reads (bsc#1054285) - CVE-2017-13722: Malformed PCF file could have caused DoS or leak information (bsc#1049692) - Prevent the X server from accessing arbitrary files as root. It is not possible to leak information, but special files can be touched allowing for causing side effects (bsc#1050459)
References: https://www.suse.com/support/update/announcement/2018/suse-su-20180246-1/, https://bugzilla.suse.com/1049692, https://bugzilla.suse.com/1050459, https://bugzilla.suse.com/1054285, https://bugzilla.suse.com/1065386, https://www.suse.com/security/cve/CVE-2017-13720, https://www.suse.com/security/cve/CVE-2017-13722, https://www.suse.com/security/cve/CVE-2017-16612
Affected packages
Package
Name: xorg-x11-libs
Purl: pkg:rpm/suse/xorg-x11-libs&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2011%20SP4
Affected ranges
Type: ECOSYSTEM
Events:
